Public arsenal
Exploits
867 indexed CVEs have a ready-to-use public exploit, 107 of them in the CISA KEV catalog and 326 affecting a tracked app.
- CVEs with exploit
- 867
- Exploits catalogued
- 1,030
- In CISA KEV
- 107
- On tracked fleet
- 326
| CVE | Severity | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2024-30896
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized u… |
CRITICAL | ExploitDB | 5% | — |
|
CVE-2026-58289
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker … |
CRITICAL | ExploitDB | 2% | — |
|
CVE-2016-2184
Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 2% | |
|
CVE-2016-3134
Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 1% | |
|
CVE-2016-6828
Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 1% | |
|
CVE-2008-0081
Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted… |
CRITICAL | ExploitDB | — | |
|
CVE-2023-44487
KEV The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams … |
HIGH | ExploitDB | 100% | |
|
CVE-2021-41773
KEV Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 |
HIGH | ExploitDB Nuclei | 100% | — |
|
CVE-2020-0688
KEV Microsoft Exchange Validation Key Remote Code Execution Vulnerability |
HIGH | ExploitDB | 100% | — |
|
CVE-2017-11882
KEV Microsoft Office Memory Corruption Vulnerability |
HIGH | ExploitDB | 100% | — |
|
CVE-2021-27065
KEV Microsoft Exchange Server Remote Code Execution Vulnerability |
HIGH | ExploitDB | 100% | — |
|
CVE-2017-0147
KEV Windows SMB Information Disclosure Vulnerability |
HIGH | ExploitDB | 100% | |
|
CVE-2024-6387
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to… |
HIGH | ExploitDB | 100% | |
|
CVE-2011-0611
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR … |
HIGH | ExploitDB | 99% | |
|
CVE-2017-0144
KEV The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2… |
HIGH | ExploitDB | 99% | |
|
CVE-2020-0618
KEV A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests… |
HIGH | ExploitDB Nuclei | 99% | — |
|
CVE-2019-5736
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 98% | — |
|
CVE-2018-20250
KEV In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE… |
HIGH | ExploitDB | 96% | |
|
CVE-2021-4034
KEV A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed… |
HIGH | ExploitDB | 95% | — |
|
CVE-2016-0189
KEV The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products,… |
HIGH | ExploitDB | 94% | — |
|
CVE-2026-43284
In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_S… |
HIGH | ExploitDB | 93% | — |
|
CVE-2026-43500
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags a… |
HIGH | ExploitDB | 93% | — |
|
CVE-2017-8570
KEV Microsoft Office Remote Code Execution Vulnerability |
HIGH | ExploitDB | 90% | — |
|
CVE-2017-0145
KEV The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2… |
HIGH | ExploitDB | 90% | |
|
CVE-2022-0847
KEV Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 90% | |
|
CVE-2020-0601
KEV Windows CryptoAPI Spoofing Vulnerability |
HIGH | ExploitDB | 89% | |
|
CVE-2016-2107
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 89% | |
|
CVE-2017-8759
KEV .NET Framework Remote Code Execution Vulnerability |
HIGH | ExploitDB | 89% | — |
|
CVE-2018-8174
KEV A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript… |
HIGH | ExploitDB | 89% | |
|
CVE-2016-9079
KEV A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered i… |
HIGH | ExploitDB | 87% | |
|
CVE-2017-14491
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 85% | |
|
CVE-2018-17463
Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code… |
HIGH | ExploitDB | 85% | |
|
CVE-2017-0213
KEV Windows COM Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 84% | |
|
CVE-2025-1098
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mir… |
HIGH | ExploitDB Nuclei | 83% | — |
|
CVE-2019-0539
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft E… |
HIGH | ExploitDB | 83% | |
|
CVE-2016-7200
KEV The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s… |
HIGH | ExploitDB | 82% | |
|
CVE-2017-0038
Windows GDI Information Disclosure Vulnerability |
HIGH | ExploitDB | 82% | |
|
CVE-2018-0886
CredSSP Remote Code Execution Vulnerability |
HIGH | ExploitDB | 82% | |
|
CVE-2019-0752
KEV A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer,… |
HIGH | ExploitDB | 82% | — |
|
CVE-2023-4911
KEV Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 81% | — |
|
CVE-2016-7255
KEV Win32k Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 81% | |
|
CVE-2018-0758
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i… |
HIGH | ExploitDB | 81% | |
|
CVE-2025-33073
KEV Windows SMB Client Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 80% | |
|
CVE-2017-0037
KEV Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::Handle… |
HIGH | ExploitDB | 80% | |
|
CVE-2019-0567
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft E… |
HIGH | ExploitDB | 80% | |
|
CVE-2016-7201
KEV The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s… |
HIGH | ExploitDB | 80% | |
|
CVE-2018-0769
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i… |
HIGH | ExploitDB | 79% | |
|
CVE-2020-6418
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via… |
HIGH | ExploitDB | 79% | |
|
CVE-2017-0070
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memo… |
HIGH | ExploitDB | 79% | |
|
CVE-2018-0770
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i… |
HIGH | ExploitDB | 78% |
Exploits aggregated from ExploitDB, Nuclei, Metasploit and GitHub PoCs, mapped to the CVEs Scout indexes. For defensive research and exposure testing only.